Astonous Trust Center

Security and privacy at Astonous

Welcome to the Astonous Trust Center. Astonous Ship and ZapBills are Salesforce-native applications, designed from the ground up to run inside your own Salesforce environment.

AppExchange Security Review

Both apps passed Salesforce’s mandatory review before listing.

ISO 9001:2015 certified

Certificate INQ/AN-26126/129996/0126 — valid to 30 Jan 2029.

No standing access

We run no database holding your Salesforce, shipment or billing data.

All documents

Documents

Astonous Ship and ZapBills were built from the ground up to run inside your own Salesforce environment. These documents are how we show that, rather than ask you to take our word for it — and all of them are open.

CERTIFICATION

ISO 9001:2015 Certificate

Certificate of registration for our quality management system, covering software development services and SaaS. Certificate No. INQ/AN-26126/129996/0126, issued by UAMLS, valid 31 Jan 2026 to 30 Jan 2029.

PDF · Updated Aug 2026

SECURITY

Trust Center Overview

The short version of this page: how each application works, what leaves your org, and where to find the detail behind every claim.

PDF · Updated 8 Sep 2026

SECURITY

Security & Privacy FAQ

Direct answers to the questions security and procurement teams ask most — data access, storage, encryption, payments, incidents and compliance.

PDF · Updated 8 Sep 2026

SECURITY

Security Self-Assessment

A control-by-control checklist in SIG-lite / CAIQ-lite style, showing what is implemented today and what is still on the roadmap. Drop it straight into your vendor questionnaire.

PDF · Updated 8 Sep 2026

POLICIES

Information Security Policy

Our internal security programme: acceptable use, access control, encryption, vendor management, incident response, training and continuous monitoring.

PDF · Updated 8 Sep 2026

SECURITY

Subprocessor & Data Flow Disclosure

Every third party each application talks to, what data reaches them, and who controls that relationship. Astonous operates no server in either data path.

PDF · Updated 8 Sep 2026

POLICIES

Vulnerability Disclosure Policy

How to report a security issue, what is in and out of scope, our response timelines, and our safe-harbour commitment to researchers.

PDF · Updated 8 Sep 2026

LEGAL

Privacy Policy

How we handle personal data across astonous.com and both applications, including how our apps handle data inside your Salesforce org.

PDF · Updated 8 Sep 2026

LEGAL

Astonous Ship MSA

The master subscription agreement covering your use of Astonous Ship.

PDF · Updated 8 Sep 2026

LEGAL

ZapBills Master Subscription Agreement

The master subscription agreement covering ZapBills, including the terms for your connected accounting platform and Stripe account.

PDF · Updated 8 Sep 2026

Working through a vendor security review?

Send us your questionnaire and we will fill it out directly. A named person answers, not a ticket queue.

shailendra.singh@astonous.com

Six answers your security team needs

The short version. Full detail sits in the Security & Privacy FAQ and the Information Security Policy above.

Where your data lives

Inside your own Salesforce org, in the data centre region your org is provisioned in. We do not replicate or mirror it anywhere.

What leaves your org

Astonous Ship sends only the address and package details a shipment needs, to the carriers you connect. ZapBills sends invoicing and payment data to your own accounting platform and Stripe account.

Who can access it

Nobody at Astonous by default. There is no standing access and no support back door. If you grant Salesforce login access for troubleshooting, that is your choice and you can revoke it at any time.

Encryption

TLS 1.2 or higher on every API call our applications make. AES-256 at rest for the limited billing and support data Astonous does hold.

Access control at Astonous

MFA is mandatory for all staff. Permissions are role-based and audited regularly, passwords are minimum twelve characters and rotate every ninety days.

If something goes wrong

A documented incident response process — log, contain, eradicate, review — with prompt notification to affected customers and regulators as legally and contractually required.

Meet the people accountable for your data and its security

Shailendra Singh Parmar

Founder, CEO, & Salesforce Architect

“We decided early that we would never hold our customers’ data. It costs us some flexibility as a product company, but it means the worst thing that can happen to a customer who trusts us is a much smaller thing. That is a trade worth making every time.”

Nidhi Bhadauriya

Director & Head of Human Resources

“Every package we ship runs inside your org and obeys the permissions you have already set — we do not ask you to loosen anything for us. Our consultants work through accounts you own and can switch off in a second, and nothing goes home with us when a project ends.”

Rahul Mittal

Salesforce Practice
Head

“A security question should not have to travel through a sales process to reach someone who can answer it. Send yours straight to me. I would rather give you an uncomfortable answer in week one than a comfortable one you discover was wrong in week six.”

How we protect your data

Three relationships, three honest answers. Read the one that applies to you.

Multi-carrier shipping, native to the Salesforce Platform and listed on the AppExchange.

Where your data lives

Inside your own Salesforce org. All application logic runs in your environment and we operate no database that stores a copy of it.

Who it is sent to

The carriers you choose to connect. Each carrier’s standard API is called directly from your Salesforce environment, using your account and credentials.

Who can access it

Your users, under your own profiles and permission sets. Astonous has no standing access and no support back door.

Support access

Only through the Salesforce login access you may choose to grant — your decision, revocable at any time, and fully logged.

Encryption

TLS 1.2 or higher on every API call the application makes.

Security review

Passed the Salesforce AppExchange mandatory review, covering injection flaws, insecure data handling and unsafe platform use.

Company_logo
Invoicing, payment collection and accounting sync, native to the Salesforce Platform.

Where your data lives

Inside your own Salesforce org. Invoices, billing records and customer details stay in the objects ZapBills creates there.

Card and payment data

ZapBills is not a payment processor or money transmitter. Card details are handled inside Stripe’s PCI DSS Level 1 certified infrastructure; we never receive or store raw card data.

Your funds

Payments flow through your own Stripe account, which you control. Astonous never receives, holds or has custody of them.

Who it is sent to

Only the platforms you connect and own — your accounting platform such as QuickBooks or Xero, and your Stripe account.

Who can access it

Your users, under your permission model. Astonous has no standing access to your org or to your connected platforms.

Security review

Passed the Salesforce AppExchange mandatory review.

Salesforce implementation, integration and managed services delivered by our consultants.

How access works

Through accounts you create and own. MFA is mandatory for our staff, permissions are role-based and reviewed regularly, and only authorised devices may be used.

Copies of your data

We do not store or process customer data locally. Where temporary storage is genuinely required, such as a data migration, secure deletion practices follow.

Removable storage

Not permitted. All data stays within approved cloud systems — no USB drives or external media on Astonous devices.

When a project ends

Access is removed and the team member’s machine is formatted, so no residual customer data remains on our hardware.

Remote work

MFA is required for any remote access. Office WiFi uses WPA3 encryption, with guest networks isolated from corporate networks.

Training

Security awareness training covering phishing, password hygiene and customer data protection — mandatory at onboarding and annually.

Still reviewing us?

Send us your security questionnaire and we will fill it out directly. Security and privacy questions go to shailendra.singh@astonous.com

shailendra.singh@astonous.com
DREAMFORCE 2026 See Astonous Ship live at Dreamforce 2026 September 15–17 · San Francisco Book a Demo →